Networking Forums

Networking Forums > Computer Networking > Windows Networking > DNS Resolution in a DMZ

Reply
Thread Tools Display Modes

DNS Resolution in a DMZ

 
 
Dave Turner
Guest
Posts: n/a

 
      09-15-2004, 01:25 PM
I'm trying to join a server to a domain from a NATd subnet in a DMZ. However
because of the NAT the DNS lookup is resolving to the real IP address of the
DC's when looking for SRV records. Has anyone got a work around for this
that does not require RRAS or ISA Server?
Thanks
Dave


 
Reply With Quote
 
 
 
 
Phillip Windell
Guest
Posts: n/a

 
      09-15-2004, 02:03 PM
The best solution is to just not do it. This is something that you shouldn't
even want to do in the first place. It would about half nullify to whole
purpose of the DMZ. The DMZ is supposed to be isolated from the LAN, or
there isn't any point of having it.

The most straight forward way I can think of is to use VPN with the DNS
being a "VPN Client" that dials into a VPN Server that sits at the boundary
between the LAN and DMZ. It is still not a very secure solution, but it is
better than nothing I guess.

Here are links to what might be some other interesting reading:

Active Directory in Networks Segmented by Firewalls
http://www.microsoft.com/windows2000...y/adsegment.as
p

303503 - How to Join or Access an Internal Domain from an External Client
Using ISA Server and VPN
http://support.microsoft.com/default...b;en-us;303503

838239 - How to use virtual private networking to join or access an internal
domain from an external client
http://support.microsoft.com/default...b;en-us;838239


--

Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com


"Dave Turner" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> I'm trying to join a server to a domain from a NATd subnet in a DMZ.

However
> because of the NAT the DNS lookup is resolving to the real IP address of

the
> DC's when looking for SRV records. Has anyone got a work around for this
> that does not require RRAS or ISA Server?
> Thanks
> Dave
>
>



 
Reply With Quote
 
Jetro
Guest
Posts: n/a

 
      09-16-2004, 03:18 PM
I'd say it completely undermines the DMZ and security principles.
If DMZ is within striking distance, install the software firewall and second
NIC into the server.


 
Reply With Quote
 
Phillip Windell
Guest
Posts: n/a

 
      09-16-2004, 04:13 PM
"Jetro" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> I'd say it completely undermines the DMZ and security principles.


Yes. I don't even like giving people any instruction to do this and would
feel like I am "contributing to crime" when they get wacked. But people are
gonna do what they are gonna do no matter what I warn them about anyway.

--

Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com


 
Reply With Quote
 
Jetro
Guest
Posts: n/a

 
      09-16-2004, 04:44 PM
Exactly. People are gonna do what they are gonna do despite the warnings
from Heaven.


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Name Resolution via VPN chrissy.stefanyshin@siga.sk.ca Windows Networking 1 08-15-2007 02:37 AM
Name resolution KM Windows Networking 3 05-14-2004 02:11 AM
Name resolution Jerry Paquette Windows Networking 0 02-27-2004 02:07 PM
No DNS resolution Mike C Windows Networking 9 02-22-2004 09:06 PM
IP resolution. =?Utf-8?B?S2FuZ2FyZWxsbw==?= Windows Networking 1 12-07-2003 11:53 PM



1 2 3 4 5 6 7 8 9 10 11